CVE-2020-9289
published 2020-06-16CVE-2020-9289: Use of a hard-coded cryptographic key to encrypt password data in CLI configuration in FortiManager 6.2.3 and below, FortiAnalyzer 6.2.3 and below may allow an…
PriorityP344high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
EPSS
2.15%
80.1th percentile
Use of a hard-coded cryptographic key to encrypt password data in CLI configuration in FortiManager 6.2.3 and below, FortiAnalyzer 6.2.3 and below may allow an attacker with access to the CLI configuration or the CLI backup file to decrypt the sensitive data, via knowledge of the hard-coded key.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| fortinet | fortianalyzer | <= 6.2.3 | — |
| fortinet | fortianalyzer | — | — |
| fortinet | fortimanager | <= 6.2.3 | — |
| fortinet | fortimanager | — | — |
| fortinet | fortios | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-8832-m7jx-c7wv: Use of a hard-coded cryptographic key to encrypt password data in CLI configuration in FortiManager 6
ghsa_unreviewed·2022-05-24
CVE-2020-9289 [MEDIUM] CWE-798 GHSA-8832-m7jx-c7wv: Use of a hard-coded cryptographic key to encrypt password data in CLI configuration in FortiManager 6
Use of a hard-coded cryptographic key to encrypt password data in CLI configuration in FortiManager 6.2.3 and below may allow an attacker with access to the CLI configuration or the CLI backup file to decrypt the sensitive data, via knowledge of the hard-coded key.
Fortinet
Use of a hard-coded cryptographic key to cipher sensitive data in FortiOS configuration backup file may allow an attacke...
vendor_fortinet·2019-11-21·CVSS 7.5
CVE-2019-6693 [MEDIUM] CWE-798 Use of a hard-coded cryptographic key to cipher sensitive data in FortiOS configuration backup file may allow an attacke...
FG-IR-19-007: Use of a hard-coded cryptographic key to cipher sensitive data in FortiOS configuration backup file may allow an attacke...
Use of a hard-coded cryptographic key to cipher sensitive data in FortiOS configuration backup file may allow an attacker with access to the backup file to decipher the sensitive data, via knowledge of the hard-coded key. The aforementioned sensitive data includes users' passwords (except the administrator's password), private keys' passphrases and High Availability password (when set).
Use of a hard-coded cryptographic key to encrypt password data in CLI configuration in FortiManager 6.2.3 and below, FortiAnalyzer 6.2.3 and below may allow an attacker with access to the CLI configuration or the CLI backup file to decrypt the sensitive data, via knowle
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2020-06-16
Published